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DETAILED ACTION 

1. Claims 1-20 remain for examination. The correspondence filed 10/19/07 
amended claims 1, 7, and 13; and added claim 20. 

f 

Continued Examination Under 37 CFR 1.114 

2. A request for continued examination under 37 CFR 1.114, including the fee set 
forth in 37 CFR 1 .17(e), was filed in this application after final rejection. Since this 
application is eligible for continued examination under 37 CFR 1.1 14, and the fee set 
forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action 
has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 
10/19/07 has been entered! 

Response to Arguments 

3. Applicant's arguments filed 10/19/07 have been fully considered but they are not 
persuasive. Applicant alleges that the P-Synch Installation Guide of 2002 fails to qualify 
as prior art, based on two observations regarding the reference: 

1) The document contains a copyright declaration of 2004; and 

2) The document repeatedly declares itself "intentionally obsolete". 

Examiner respectfully submits that these issues are insufficient to discredit version 6.2 
of the P-Synch software product as prior art, based on evidence discovered by the 
Examiner in response to the amendment of 10/19/07. 
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First, it is noted that the Internet Archive has cached many documents regarding 
earlier versions of the P-Synch product. For example, a press release establishes that 
version 6.2 of the software (the particular version described by the reference) was 
initially released for sale to the public on May 2, 2002. Furthermore, based on the 
version history of the various revisions of the P-Synch Installation Guide for version 6.x, 
the subject matter found in the document revision 0.104 reflected the then-current state 
of that software until the Guide was revised into version 0.138 in September 2002. 
Giving Applicant the benefit of the doubt, the subject matter of revision 0.1 04 of the 
Guide describes the P-Synch v6.2 product as it existed between May 2, 2002 (the 
official release date) through no later than September 30, 2002; in any event, that is 
more than one year prior to the effective filing date in the U.S. of the instant application. 

Second, it is further observed that at the time of the invention, the P-Synch 
vendor, M-Tech, provided both HTML and PDF copies of the installation guide on the 
. website; however, at the present time only PDF copies of the Guide(s) are available. As 
. the Internet Archive attests, many HTML copies of the Guide describing the P-Synch 
v6.x product; both pre-dating and post-dating revision 0.104, were published well before 
2004. Examiner submits that the 2004 copyright date refers only to the re-issuance of 
the Guide in PDF form, said Guide comprising information from the HTML version which 
had not changed since May 2002. 1 As to the issue of why the PDF is designated 
"obsolete" - in addition to the plainly apparent fact that the Guide was revised several 

1 While the HTML versions of the Installation Guide on the Internet Archive are indisputably prior art, 
Examiner will continue to quote from the PDF as a matter of convenience; obtaining individual printouts of 
the hundreds of individual web pages comprising the HTML Guide would present an undue burden on the 
Examiner, requiring far more time to produce than is allotted to the Examiner for responding in this case. 
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times between the release of P-Synch v6.2 and the effective filing date of the instant 
application - a close inspection of the metadata found in each of the PDF files of the 

2002 and 2003 revisions of the Guide entered on the record show that the PDF of the 

2003 manual - which at the time of this Office Action is promulgated by M-Tech on their 
website as the current version of the Guide - was produced on May 26, 2004; while the 
PDF of the obsolete 2002 manual was subsequently produced on July 14, 2004. It is 
reasonable to assume that M-Tech, in creating the latter PDF from pre-existing [HTML] 
copies of the Guide, would have been well aware that said PDF was obsolete in view of 
the former PDF with more recent subject matter, and thus could have reasonably 
wanted to indicate such on any future re-issue of older revision(s) of the Guide. 
Applicant is invited to directly verify the creation dates of the PDF files from the M-Tech 
website at the URLs http://www.psvnch.com/docs/instguide.pdf [2002 revision] and 
http://www.psynch.com/docs/psynch-manual.pdf [2003 revision]. 

Based on the preponderance of evidence above, Examiner maintains that the P- 
Synch software product (version 6.2), as attested by the P-Synch Installation and 
Configuration Guide (document revision 0.104) remains valid for use in a rejection 
under 35 USC 102(b). Nevertheless, Examiner believes the discussion on the merits of 
that reference as prior art is moot in view of the P-Synch Installation and Administration 
Guide for software version 4.2 (©2000 M-Tech), that discloses an even older version of 
P-Synch in sufficient detail to read on each and every limitation of the claims. 

As to the new limitations in amended claims 1 , 7, and 13, the P-Synch Guide(s) 
disclose these limitations in passages of those references that were not previously 
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supplied to the Applicant, as said passages were not pertinent to the claimed invention 
prior to the amendment of 10/19/07. The additional passages are enclosed herein. 

In order to expedite prosecution of the instant application, Examiner has 
voluntarily withdrawn those rejections of the claims involving the Linux Journal article 
and the SPM reference. This is not to be construed as an admission that the instant 
application is allowable over those references; furthermore, Examiner reserves the right 
to reinstate rejections based upon them at a future time as may be warranted by future 
amendments to the claims. 

Claim Rejections - 35 USC § 102 

4. The text of those sections of Title 35, U.S. Code not included in this action can 
be found in a prior Office action. 

5. Claims 1-20 are rejected under 35 U.S.C. 102(b) based upon a public use or sale 
of the invention: P-Synch version 6.2 (available for public sale on May 2, 2002) 
implements all the limitations of the rejected claims, as evidenced by the P-Synch 
Installation and Configuration Guide, revision 0.104, last revised on May 2002. 

Regarding claim 1: 

P-Synch discloses a tool for managing passwords, comprising: storage for a 
plurality of current passwords for a plurality of respective applications (page 7, section 
"2.4 Self-service profile management"; cf. the chart on page 20), and for each of said 
applications: a description of the application (page 14, "3.3 Target Systems"), a 
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description of the password type for the application (Ibid); current and previous 
passwords for the application (page 126: password history), and a Uniform Resource 
Locator for the application (page 14, "3.3 Target Systems"; cf. Table 5-1 on page 20); 
means for displaying a reminder to change one or more passwords ("Password expiry 
early notification client" on pages 122-123); and a script for simulating keystroke entries, 
or running an executable program, to automatically perform a password change in said 
respective applications for said current passwords of said reminder (e.g. pages 585- 
587) wherein the script tests proposed new passwords to determine if said proposed 
new passwords meet a defined criteria, and the script changes a password only if the 
proposed new password meets the defined criteria (e.g. page 2, "Enforcing strong 
password rules..."). 

Regarding claims 7 and 13: 

P-Synch discloses a method and program storage device comprising: 
accumulating a set of passwords in a password management facility, each of said 
passwords being associated with a computer application having a password change 
procedure (page 7, section "2.4 Self-service profile management"; cf. the chart on page 
20); storing in the password management facility, for each of said applications: a 
description of the application (page 14, "3.3 Target Systems"), a description of the 
password type for the application (Ibid); current and previous passwords for the 
application (page 126: password history), and a Uniform Resource Locator for the 
application (page 14, "3.3 Target Systems"; cf. Table 5-1 On page 20); providing the 
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password management facility with a set of scripts to operate the password change 
procedures of the associated applications (e.g. pages 585-587); and invoking the scripts 
to change passwords (Ibid). Per claim 7, P-Synch further discloses wherein the scripts 
test proposed new passwords to determine if said proposed new passwords meet a 
defined criteria, and the scripts change a password only if the proposed new password 
meets the defined criteria (pages 2, 4, and 124-126). 

Regarding claims 2,11, and 17: 

P-Synch further discloses wherein the applications are selected from the group 
including workstation applications, legacy host applications, server applications, and 
networked applications (page 20, Table 5.1). 

Regarding claim 3: 

P-Synch further discloses means for displaying a list of passwords (Figure 12.2. 
on page 186) and means for displaying a graphical user interface for invoking the script 
to change passwords (via a web browser GUI: page 190; see also page 64). 

Regarding claims 4, 9, and 15: 

P-Synch further discloses wherein the graphical user interface includes a series 
of activatable display elements, each display element being shown adjacent to one of 
the passwords to invoke script for changing said one password (pages 183-186). 
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Regarding claim 5: 

P-Synch further discloses wherein at least some of the applications include a 
password change form and require a series of actions to get to the password change 
form, and the script includes means to perform said series of actions to get to the 
password change form ("Native Password management": see page 191 etc). 

Regarding claims 6, 12, and 18: 

P-Synch further discloses wherein the passwords are encrypted in said storage 
("hashed" passwords: see page 7, "2.4 Self-service profile management"; see also the 
encrypted password cache on page 136). 

Regarding claims 8 and 14: 

P-Synch further discloses accessing the password management facility (e.g. 
pages 183-187); said password management facility displaying a list of passwords and 
a graphical user interface for invoking the scripts (Ibid); and using said graphical user 
interface to activate the scripts to change the passwords (pages 185-186). Per claim 
14, P-Synch further discloses wherein the scripts test proposed new passwords to 
determine if said proposed new passwords meet a defined criteria, and the scripts 
change a password only if the proposed new password meets the defined criteria 
(pages 2, 4, and 124-126). 
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Regarding claims 10 and 16: 

P-Synch further discloses wherein each of the scripts simulates a set of 
keystroke entries or an executable program to change the password for one of the 
applications (simulates keystrokes on page 587; runs an executable program ["native 
password change"] on page 5, "2.1.2 Transparent synchronization"). 

Regarding claim 19: 

P-Synch further discloses wherein the defined criteria are based on data from a 
user table (the user's password history table: page 7, section "2.4 Self-service profile 
management"; see also pages 124-128, particularly page 126). 

Regarding claim 20: 

P-Synch further discloses invoking the password management facility (page 
190); said facility, when invoked, displaying a graphical user interface (Ibid; cf. pages 
185-186); using said graphical interface to invoke or activate the scripts needed to 
change passwords (Ibid); displaying user prompts to obtain information from the user 
when a script or code is invoked to change one of the passwords (Ibid); encrypting all of 
the data stored in the facility (page 296, encrypted host table; cf. Table 5-1 on page 20); 
and providing different users with different degrees of access (e.g. Help-desk users vs. 
end-users: pages 50-53). 
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6. Claims 1-20 are again rejected under 35 U.S.C. 102(b) based upon a public use 
or sale of the invention. P-Synch version 4.2 implements all the limitations of the 
rejected claims, as evidenced by the P-Synch Installation and Administration Guide 
from June 1, 2000 (obtained by the Internet Archive on September 25, 2000). 

Regarding claim 1: 

P-Synch discloses a tool for managing passwords, comprising: storage for a 
plurality of current passwords for a plurality of respective applications (password history, 
pages 33 & 34), and for each of said applications: a description of the application (page 
27, "3.1 .2 Target system information"), a description of the password type for the 
application (Ibid); current and previous passwords for the application (page 7, 
"Password history"), and a Uniform Resource Locator for the application (page 27, 
"3.1.2 Target system information"; cf. page 28, Table 3.1); means for displaying a 
reminder to change one or more passwords (page 14, "Expiry detection and password 
aging"); and a script for simulating keystroke entries, or running an executable program, 
to automatically perform a password change in said respective applications for said 
current passwords of said reminder (Ibid, and pages 13-14) wherein the script tests 
proposed new passwords to determine if said proposed new passwords meet a defined 
criteria, and the script changes a password only if the proposed new password meets 
the defined criteria (page 7, "Password strength rules"; page 11, "Enforcing strong 
password rules..."). 
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Regarding claims 7 and 13: 

P-Synch discloses a method and program storage device comprising: 
accumulating a set of passwords in a password management facility, each of said 
passwords being associated with a computer application having a password change 
procedure (pages 13-15, "2.2.1 User Password Changes"); storing in the password 
management facility, for each of said applications: a description of the application (page 
27, "3.1 .2 Target system information"), a description of the password type for the 
application (Ibid); current and previous passwords for the application (page 7, 
"Password history"), and a Uniform Resource Locator for the application (page 27, 
"3.1.2. Target system information"; cf. page 28, Table 3.1); providing the password 
management facility with a set of scripts to operate the password change procedures of 
the associated applications (pages 13-15); and invoking the scripts to change 
passwords (Ibid). Per claim 7, P-Synch further discloses wherein the scripts test 
proposed new passwords to determine if said proposed new passwords meet a defined 
criteria, and the scripts change a password only if the proposed new password meets 
the defined criteria (page 7, "Password strength rules"; page 11, "Enforcing strong 
password rules..."). 

Regarding claims 2, 1 1 , and 17: 

P-Synch further discloses wherein the applications are selected from the group 
including workstation applications, legacy host applications, server applications, and 
networked applications (Table 3.1 on page 28). 
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Regarding claim 3: 

P-Synch further discloses means for displaying a list of passwords (page 49, 
"4.3.1. Overview") and means for displaying a graphical user interface for invoking the 
script to change passwords (pages 13-15). 

Regarding claims 4, 9, and 15: 

P-Synch further discloses wherein the graphical user interface includes a series 
of activatable display elements, each display element being shown adjacent to one of 
the passwords to invoke script for changing said one password (pages 13-15). 

Regarding claim 5: 

P-Synch further discloses wherein at least some of the applications include a 
password change form and require a series of actions to get to the password change 
form, and the script includes means to perform said series of actions to get to the 
password change form (e.g. the sample script on pages 192-193). 

Regarding claims 6, 12, and 18: 

P-Synch further discloses wherein the passwords are encrypted in said storage 
(pages 33 and 34, bullet point "hist\"). 
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Regarding claims 8 and 14: 

P-Synch further discloses accessing the password management facility (pages 
13-15); said password management facility displaying a list of passwords and a 
graphical user interface for invoking the scripts (Ibid); and using said graphical user 
interface to activate the scripts to change the passwords (Ibid). Per claim 14, P-Synch 
further discloses wherein the scripts test proposed new passwords to determine if said 
proposed new passwords meet a defined criteria, and the scripts change a password 
only if the proposed new password meets the defined criteria (page 7, "Password 
strength rules"). 

Regarding claims 10 and 16: 

P-Synch further discloses wherein each of the scripts simulates a set of 
keystroke entries or an executable program to change the password for one of the 
applications (Telnet scripts and Native APIs, respectively, on pages 13-15; cf. the 
sample scripts on pages 192-193). 

Regarding claim 19: 

P-Synch further discloses wherein the defined criteria are based on data from a 
user table (the user's password history table, pages 33 and 34). 
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Regarding claim 20: 

P-Synch further discloses invoking the password management facility (pages 13- 
15); said facility, when invoked, displaying a graphical user interface (Ibid); using said 
graphical interface to invoke or activate the scripts needed to change passwords (Ibid); 
displaying user prompts to obtain information from the user when a script or code is 
invoked to change one of the passwords (Ibid); encrypting all of the data stored in the 
facility (pages 33 & 34, bullet point "hist\"; cf. pages 346-347); and providing different 
users with different degrees of access (Help-desk users vs. end-users: see page 1 1, the 
third and fourth bullet points). 

Conclusion 

7. The prior art made of record and not relied upon is considered pertinent to 
applicant's disclosure: 

• "P-Synch 6.2.0 released" press release dated May 2, 2002 

• "P-Synch white paper" ©2001 M-Tech Mercury Information Technology Inc. 
(obtained by the Internet Archive on March 21 , 2002) 

• "Password Security and Identity Management" ©2002 M-Tech Inc. (obtained by 
the Internet Archive on September 29, 2002) 

• "P-Synch Documentation" [offering HTML and PDF copies of the same Guide] 
©2003 M-Tech Inc. (obtained by the Internet Archive August 6, 2003) 

• "P-Synch Documentation" web page as of 10/26/07, to establish that the May 
2003 version of the P-Synch Guide reflects the current state of the product 
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8. Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Tom Gyorfi whose telephone number is (571) 272-3849. 
The examiner can normally be reached on 8:30am - 5:00pm Monday - Friday. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Kim Vu can be reached on (571) 272-3859. The fax phone number for the 
organization where this application or proceeding is assigned is 571-273-8300. 

Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated information 
system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 

TAG 
10/26/07 
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